CVE-2020-26555 is a Bluetooth vulnerability affecting Core Specification 1.0B through 5.2, allowing an unauthenticated, nearby device to spoof a peer device's BD_ADDR during legacy BR/EDR PIN code pairing. This medium-severity flaw (CVSS 5.4) has a low attack complexity and requires physical proximity, potentially leading to limited confidentiality and integrity impacts without user interaction. While not currently in CISA's KEV catalog and lacking public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating awareness despite no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1b, <= 5.2CPE matchmatch criteria | cpe:2.3:a:bluetooth:bluetooth_core_specification:*:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:ax210_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:ax201_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:ax200_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.